Am reposting, Redirect Search and something going on with Yahoo?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Anon-60b32b33ba, May 11, 2006.

  1. Anon-60b32b33ba

    Anon-60b32b33ba Anonymized

    Redirect Search and something going on with Yahoo?

    Okay...I've gone through the Read Me First Sticky post and have search my computer and it hasn't found anything. When I search say on Google...when I click a link it'll either go to Ebay in German or to another search engine. When I click back and click the same link, I'm able to go to the page I was originally wanting.

    Also today, I noticed that when I was signed onto Yahoo...I was doing a people search. At the top of the results page where it says your user name, other people's user names were up there and not mine?

    I just don't understand....attached is a HiJack This log...oh, am on an HP laptop running WinXP home. And am using the current, non-beta version of Internet Explorer.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Redirect Search and something going on with Yahoo?

    Welcome to Majorgeeks!

    Please run ALL steps in the READ & RUN ME. At a minimum I can see you skipped step 6. You must run step 6 and attach the two logs before step 7 (HJT) is run.

    Do you know who the below file belongs to:
    O2 - BHO: (no name) - {A3E609B5-6860-47EC-A095-045D0A1DF570} - C:\WINDOWS\system32\HpHipa32.dll

    Check file Properties and Version info on C:\WINDOWS\system32\HpHipa32.dll

    Locate it using Windows Explorer and then right click on it and select Properties. Now see if there is a Version tab in the window. If so, select the Version tab and on the next window select each of the listed Item names (one at a time) to get more info about the file. The most important Item is the company name. If there is no Version tab, tell me that too.
     
    Last edited: May 11, 2006
  3. Anon-60b32b33ba

    Anon-60b32b33ba Anonymized

    Okay...I've gone through the Read Me First Sticky post and have search my computer and it hasn't found anything. When I search say on Google...when I click a link it'll either go to Ebay in German or to another search engine. When I click back and click the same link, I'm able to go to the page I was originally wanting.

    Also today, I noticed that when I was signed onto Yahoo...I was doing a people search. At the top of the results page where it says your user name, other people's user names were up there and not mine?

    I just don't understand....attached is a HiJack This log...oh, am on an HP laptop running WinXP home. And am using the current, non-beta version of Internet Explorer.

    I checked the properties of the hphipa32.dll and there was no version tab so there's no information about this file.
     

    Attached Files:

  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Merged the 2 threads to keep any info Chas needs together.
     
  5. Anon-60b32b33ba

    Anon-60b32b33ba Anonymized

    :eek: Okay, something is seriously wrong on my laptop now. When I'm typing stuff (like right now), I'll get a small delay when some of my letters won't show up like my computer's slow.

    Also, this morning when I was checking my Gmail I kept getting this message inside Gmail:

    Arrgh! The page has been corrupted. If you are running security or firewall software, you may have to disable it. Learn more (http://mail.google.com/support/bin/answer.py?ctx=gmail&hl=e&answer=19529)

    And I'm not running ANY Norton products. I have ZoneAlarm as my firewall and AVG Free as my antivirus.

    Then if I'm not getting that message I'll get this one from Internet Explorer:

    Internet Explorer cannot open the Internet site
    http://mail.google.com/mail/?auth=D...e-BpDuJe5YYlfBLaFffuIAty180eYyzPQOMvD5&shva=1.

    Operation aborted.

    OK

    When I click OK it'll give me a page not found and tell me that maybe I'm disconnected from the internet. When I click back, I get my gmail page displayed in text only. When I click refresh, I'm able to check my messages again.

    What's going on?????
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Redirect Search and something going on with Yahoo?

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {A3E609B5-6860-47EC-A095-045D0A1DF570} - C:\WINDOWS\system32\HpHipa32.dll

    After clicking Fix, exit HJT.:

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot your PC ( in normal mode )and post a new HJT log.

    Make sure you tell me how things are working now.

    If you are still having problems, run the below Ewido scan and attach the requested log:

    Running Ewido Anti-Malware
     
  7. Anon-60b32b33ba

    Anon-60b32b33ba Anonymized

    Something still doesn't seem right so I'll run that other scan. Attached is that new hijack log.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please describe "something".
     
  9. Anon-60b32b33ba

    Anon-60b32b33ba Anonymized

    It's still hanging. And when I close IE, the window I just closed will open again (but not load) and then will close again a couple seconds later. I ran Ewido but all it found was some cookies.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not appear to be a malware problem, but let's dig deeper before sending you to the Software Forum.

    What is the below for?
    O4 - HKLM\..\Run: [MegaPanel] C:\Program Files\ACNielsen\Homescan Internet Transporter\HSTrans.exe

    Let's get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
    Please run the Ewido scan I suggested and attach the log.
     
    Last edited: May 20, 2006
  11. Anon-60b32b33ba

    Anon-60b32b33ba Anonymized

    That's for a scanner I use to track what I buy at the store...kind of like surveys but with a scanner, for ACNielson (same company that does the TV ratings and all that).

    Also, today I was clicking on a link and it opened it in a new IE window but didn't load it all the way. (I've attached a picture). The window is still open and clicking on the x won't close it and ctrl+alt+del won't either because it doesn't list it as being open either. The only way to get rid of it is to close all my IE windows.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still do not see any malware problems!

    You do need to uninstall the below old Sun Java versions though:
    Java 2 Runtime Environment Standard Edition v1.3.1_03
    Java 2 Runtime Environment, SE v1.4.0
    Java 2 Runtime Environment, SE v1.4.1_02
    Java 2 SDK, SE v1.4.0

    I would suggest you either disable or uninstall (only temporarily) your ZoneAlarm firewall and see if you still have problems.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds